LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-29557: D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-29557 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

CVE-2020-29557 is a buffer overflow vulnerability in the web interface of D-Link DIR-825 R1 devices. Successful abuse may allow remote code execution on the affected router. For IT and security teams, this matters because consumer and small-office routers often sit at the network edge with management interfaces exposed or weakly protected, giving an attacker a foothold that can lead to traffic interception, lateral movement, or persistent access. Confirm all product and fix details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-119: improper restriction of operations within the bounds of a memory buffer. In plain terms, the device’s web interface fails to adequately bound or validate input before copying or processing it in memory. When an attacker supplies oversized or specially crafted data to a vulnerable interface endpoint, the overflow can corrupt adjacent memory. On embedded devices this class of flaw frequently leads to control of execution flow and, ultimately, remote code execution with the privileges of the web service or the device itself.

Public detail on the exact request parameters, authentication requirements, or exploit primitives is limited. Defenders should treat any unauthenticated or weakly authenticated access to the DIR-825 R1 web interface as a potential attack surface and verify the precise conditions in the vendor advisory rather than assuming a particular attack path.

Am I affected? How to find it in your systems

D-Link DIR-825 R1 devices are typically deployed as home, branch, or small-office wireless routers. They may appear in asset inventories as customer-premises equipment, lab gear, or forgotten edge devices still connected to production networks.

How to remediate

Patch first. Apply the updates provided by D-Link exactly as described in the vendor instructions for the DIR-825 R1. CISA’s required action is to apply updates per vendor instructions; do not rely on third-party summaries for version strings or download locations.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the underlying memory-corruption flaw; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited router vulnerabilities can lead to credential theft, traffic interception, or broader network compromise.<|eos|>

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-825 R1 Devices
WeaknessCWE-119
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities